Where
AND
-Infinity
0
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Fix potential ADE in loongsongpufixupdmahang()

The switch case in loongsongpufixupdmahang() may not DC2 or DC3, and readl(crtcreg) will access with random address, because the "device" is from "base+PCIDEVICEID", "base" is from "pdev->devfn+1". This is wrong when my platform inserts a discrete GPU:

lspci -tv -[0000:00]-+-00.0 Loongson Technology LLC Hyper Transport Bridge Controller ... +-06.0 Loongson Technology LLC LG100 GPU +-06.2 Loongson Technology LLC Device 7a37 ...

Add a default switch case to fix the panic as below:

Kernel ade access[#1]: CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.6.136-loong64-desktop-hwe+ #4 pc 90000000017e5534 ra 90000000017e54c0 tp 90000001002f8000 sp 90000001002fb6c0 a0 80000efe00003100 a1 0000000000003100 a2 0000000000000000 a3 0000000000000002 a4 90000001002fb6b4 a5 900000087cdb58fd a6 90000000027af000 a7 0000000000000001 t0 00000000000085b9 t1 000000000000ffff t2 0000000000000000 t3 0000000000000000 t4 fffffffffffffffd t5 00000000fffb6d9c t6 0000000000083b00 t7 00000000000070c0 t8 900000087cdb4d94 u0 900000087cdb58fd s9 90000001002fb826 s0 90000000031c12c8 s1 7fffffffffffff00 s2 90000000031c12d0 s3 0000000000002710 s4 0000000000000000 s5 0000000000000000 s6 9000000100053000 s7 7fffffffffffff00 s8 90000000030d4000 ra: 90000000017e54c0 loongsongpufixupdmahang+0x40/0x210 ERA: 90000000017e5534 loongsongpufixupdmahang+0xb4/0x210 CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) PRMD: 00000004 (PPLV0 +PIE -PWE) EUEN: 00000000 (-FPE -SXE -ASXE -BTE) ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7) ESTAT: 00480000 [ADEM] (IS= ECode=8 EsubCode=1) BADV: 7fffffffffffff00 PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV) Modules linked in: Process swapper/0 (pid: 1, threadinfo=(ptrval), task=(ptrval)) Stack : 0000000000000006 90000001002fb778 90000001002fb704 0000000000000007 0000000016a65700 90000000017e5690 000000000000ffff ffffffffffffffff 900000000209f7c0 9000000100053000 900000000209f7a8 9000000000eebc08 0000000000000000 0000000000000000 0000000000000006 90000001002fb778 90000001000530b8 90000000027af000 0000000000000000 9000000100054000 9000000100053000 9000000000ebb70c 9000000100004c00 9000000004000001 90000001002fb7e4 bae765461f31cb12 0000000000000000 0000000000000000 0000000000000006 90000000027af000 0000000000000030 90000000027af000 900000087cd6f800 9000000100053000 0000000000000000 9000000000ebc560 7a2500147cdaf720 bae765461f31cb12 0000000000000001 0000000000000030 ... Call Trace: [<90000000017e5534>] loongsongpufixupdmahang+0xb4/0x210 [<9000000000eebc08>] pcifixupdevice+0x108/0x280 [<9000000000ebb70c>] pcisetupdevice+0x24c/0x690 [<9000000000ebc560>] pciscansingledevice+0xe0/0x140 [<9000000000ebc684>] pciscanslot+0xc4/0x280 [<9000000000ebdd00>] pciscanchildbusextend+0x60/0x3f0 [<9000000000f5bc94>] acpipcirootcreate+0x2b4/0x420 [<90000000017e5e74>] pciacpiscanroot+0x2d4/0x440 [<9000000000f5b02c>] acpipcirootadd+0x21c/0x3a0 [<9000000000f4ee54>] acpibusattach+0x1a4/0x3c0 [<90000000010e200c>] deviceforeachchild+0x6c/0xe0 [<9000000000f4bbf4>] acpidevforeachchild+0x44/0x70 [<9000000000f4ef40>] acpibusattach+0x290/0x3c0 [<90000000010e200c>] deviceforeachchild+0x6c/0xe0 [<9000000000f4bbf4>] acpidevforeachchild+0x44/0x70 [<9000000000f4ef40>] acpibusattach+0x290/0x3c0 [<9000000000f5211c>] acpibusscan+0x6c/0x280 [<900000000189c028>] acpiscaninit+0x194/0x310 [<900000000189bc6c>] acpiinit+0xcc/0x140 [<9000000000220cdc>] dooneinitcall+0x4c/0x310 [<90000000018618fc>] kernelinitfreeable+0x258/0x2d4 [<900000000184326c>] kernelinit+0x28/0x13c [<9000000000222008>] retfromkernelthread+0xc/0xa4

1 / 2
Source: MITRE
First published (updated )
Severity
5.5
Null Pointer Dereference
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Fix missing NULL checks for kstrdup()

1. Replace "offindnodebypath("/")" with "ofroot" to avoid multiple calls to "ofnodeput()".

2. Fix a potential kernel oops during early boot when memory allocation fails while parsing CPU model from device tree.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203